Inside the advisory: how the alleged extraction pipeline works
On September 8, 2026, the NSA, CISA, and FBI released a joint cybersecurity advisory, AA26-251A, accusing six China-based AI companies of conducting industrial-scale knowledge distillation against US frontier models since at least late 2024 [1]. Knowledge distillation itself is not exotic: a smaller 'student' model is trained to mimic the outputs of a larger 'teacher' model, learning to approximate its reasoning patterns without needing the teacher's original training data or compute budget. What the advisory alleges is different in scale and method. It says the accused firms treated distillation as 'the core - not merely a supplement - of their AI development strategy,' and routed requests through native APIs, remote cloud providers, and third-party aggregators specifically chosen to obscure user metadata and evade the target companies' terms of use [2]. The advisory also identifies a gray market of proxy services called 'transfer stations,' reportedly marketed on Chinese platforms Taobao and Xianyu, that bypass geographic restrictions and safeguards, alongside bulk purchases of premium subscriptions shared across developer teams to keep the cost of extraction low [3].



